It's not just OpenAI models that have gone rogue. Claude Cowork could read files on Mac it shouldn't have had access to Home News Security experts showed that the AI tool Claude Cowork was able to escape its isolated environment on Mac The agent thus gained access to private files across the entire user account, including access keys and cloud passwords This follows a recent case where two OpenAI models escaped from the lab Sdílejte: Adam Kurfürst Published: 28. 7. 2026 10:30 Advertisement A few days ago, we wrote about how OpenAI lost control of its models during a test and they breached a third-party company. Now it turns out that a similar vulnerability doesn’t only plague the competition: security firm Accomplish demonstrated that even Anthropic’s Claude Cowork was able to bypass its own sandbox and access files it should have been completely out of reach of. Smart assistant escaped from isolated environment Claude Cowork is an AI assistant from Anthropic that performs tasks for you on your computer – it goes through a folder, modifies files, finds something. To prevent it from causing damage, it runs enclosed in its own isolated environment (technically a sandbox, a kind of “sandpit”) and should only see the single folder you give it access to. However, this boundary was successfully breached. Researchers from Accomplish started a fresh session, shared a single folder with the agent, and sent it one short message. “We watched the agent escape the sandbox,” described one of them, Oren Yomtov. Instead of staying within the defined space, it spread to files across the entire account. Agent could access sensitive data Once the agent was out of the sandbox, it could read and overwrite files anywhere in the account – even where a regular program is not allowed without permission. Among what it was able to read were login keys and access credentials for cloud services – precisely the sensitive information with which a potential attacker can cause the most damage. It's not just OpenAI models that have gone rogue. Claude Cowork could read files on Mac it shouldn't have had access to Adam Kurfürst News Adam Kurfürst News According to the researchers, the problem affected approximately half a million people who ran Cowork directly on their Macs. It should be added that this was not a real external attack – it was a controlled demonstration by security experts who described and reported the vulnerability. However, the risk was entirely real. How did Anthropic react? According to the researchers, the company closed the report as “informative” without issuing a direct fix. However, newer versions of Cowork by default run in the cloud, not directly on your computer – thus bypassing the escape route from Mac. But anyone who knowingly enables it to run directly on the device remains exposed to risk, according to experts. Both cases – the escaped OpenAI models and this Cowork vulnerability – follow the same pattern. We are giving artificial intelligence more and more autonomy and access to our data, but the walls meant to keep it in check are not yet as strong as they first appear. Would you let an AI assistant access files directly on your computer? Sources: Accomplish, The Hacker News, TechRadar About the author Adam Kurfürst Adam studuje na gymnáziu a technologické žurnalistice se věnuje od svých 14 let. Pakliže pomineme jeho vášeň pro chytré telefony, tablety a příslušenství, rád se… More about the author Sdílejte: Anthropic bezpečnost Claude macOS OpenAI Umělá inteligence